If you're developing a FOSS project, be aware of cryptobros trying to PR a tea.yml into it.

db0@lemmy.dbzer0.com to Open Source@lemmy.ml – 418 points –
The disappointing tea.xyz
connortumbleson.com

Yet another "brilliant" scheme from a cryptobro. Naturally this caused a gold-rush for scammers who outsourced random people via the gig economy to open PRs for this yml file (example)

96

You are viewing a single comment

Honestly doesn't sound like a terrible idea on paper, but this spam outbreak could kill it before it gets off paper in a real way. Giving devs a bad taste will stay around a long while.

Edit: and of course the well-earned general attitude toward cryptocurrency as scammer playgrounds is automatically putting it way in the red too.

Dude also used a LLM to generate descriptions for the packages he's serving from his package manager. And of course, it got them wrong, creating a headache for the actual package maintainers

I do like the idea of streamlining donations to open source projects directly through a package manager, and crypto seems like a good fit for that (decentralized, uncensorable). The issue here seems similar to knowing what charities are properly using funds; making a system to make decisions about how to spend money is hard when there's so many people looking to misdirect it to themselves, and the point of this would be to relieve the people who would be donating the money from putting effort into doing the research themselves, so that big problem has to be solved.